HIGH

CVE-2023-33107

Qualcomm 315 5g Iot Modem Firmware 2023-12-05 CVSS v3.1
CVSS
7.8
KEV

Description

Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

Summary dbcve.org

Memory corruption vulnerability in the Linux graphics driver that occurs when assigning a shared virtual memory region during an IOCTL call. The flaw allows a local attacker with low privileges to potentially execute arbitrary code or cause a denial of service via crafted IOCTL requests.

Mitigation

Apply vendor-supplied patches for the Linux graphics driver; update to patched kernel/driver versions. Restrict access to graphics IOCTL interfaces for untrusted users as an interim mitigation.

Patch Commit

Weakness (CWE)

CWE-190 Integer Overflow

EPSS Score

0.89%
Probability of exploitation in next 30 days
57.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE